SportsPress for Cricket Security & Risk Analysis

wordpress.org/plugins/sportspress-for-cricket

SportsPress for Cricket is an extension for SportsPress, an all-in-one sports data plugin that helps sports clubs set up a cricket website.

600 active installs v1.1.4 PHP + WP 3.8+ Updated Aug 27, 2020
playerssportsportsstatisticsstats
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SportsPress for Cricket Safe to Use in 2026?

Generally Safe

Score 85/100

SportsPress for Cricket has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The sportspress-for-cricket plugin v1.1.4 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. The code also demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage of output escaping (86%). Furthermore, the plugin incorporates nonce and capability checks, indicating an effort to protect against common WordPress vulnerabilities. The complete lack of known CVEs and a clean vulnerability history strongly suggests a well-maintained and secure plugin.

While the analysis reveals no immediate critical risks such as taint flows with unsanitized paths or dangerous functions, the limited attack surface itself is a notable strength. The fact that all identified SQL queries are prepared is excellent. The slight percentage of unescaped output (14%) is a minor concern but given the limited attack surface and lack of identified vulnerabilities, it's unlikely to pose a significant risk in this specific version. The overall picture is one of a secure plugin with good development practices.

Key Concerns

  • Unescaped output exists
Vulnerabilities
None known

SportsPress for Cricket Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SportsPress for Cricket Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
83 escaped
Nonce Checks
5
Capability Checks
13
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped96 total outputs
Attack Surface

SportsPress for Cricket Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 47
actioninitincludes\class-tgm-plugin-activation.php:268
filterload_textdomain_mofileincludes\class-tgm-plugin-activation.php:269
actioninitincludes\class-tgm-plugin-activation.php:272
actionadmin_menuincludes\class-tgm-plugin-activation.php:421
actionadmin_headincludes\class-tgm-plugin-activation.php:422
filterinstall_plugin_complete_actionsincludes\class-tgm-plugin-activation.php:425
filterupdate_plugin_complete_actionsincludes\class-tgm-plugin-activation.php:426
actionadmin_noticesincludes\class-tgm-plugin-activation.php:429
actionadmin_initincludes\class-tgm-plugin-activation.php:430
actionadmin_enqueue_scriptsincludes\class-tgm-plugin-activation.php:431
actionload-plugins.phpincludes\class-tgm-plugin-activation.php:436
actionswitch_themeincludes\class-tgm-plugin-activation.php:439
actionswitch_themeincludes\class-tgm-plugin-activation.php:442
actionadmin_initincludes\class-tgm-plugin-activation.php:447
actionswitch_themeincludes\class-tgm-plugin-activation.php:452
actionload_textdomain_mofileincludes\class-tgm-plugin-activation.php:475
filterupgrader_source_selectionincludes\class-tgm-plugin-activation.php:889
actionplugins_loadedincludes\class-tgm-plugin-activation.php:2112
filtertgmpa_table_data_itemsincludes\class-tgm-plugin-activation.php:2236
filterupgrader_source_selectionincludes\class-tgm-plugin-activation.php:2977
actionadmin_initincludes\class-tgm-plugin-activation.php:3147
actionupgrader_process_completeincludes\class-tgm-plugin-activation.php:3242
filterupgrader_post_installincludes\class-tgm-plugin-activation.php:3301
filterupgrader_post_installincludes\class-tgm-plugin-activation.php:3446
actioninitsportspress-for-cricket.php:38
actionget_the_generator_htmlsportspress-for-cricket.php:41
actionget_the_generator_xhtmlsportspress-for-cricket.php:42
actiontgmpa_registersportspress-for-cricket.php:45
actionwp_enqueue_scriptssportspress-for-cricket.php:48
actionadmin_enqueue_scriptssportspress-for-cricket.php:49
filtersportspress_enqueue_stylessportspress-for-cricket.php:50
filtergettextsportspress-for-cricket.php:53
actionsportspress_event_performance_meta_box_table_footersportspress-for-cricket.php:56
actionsportspress_event_performance_table_footersportspress-for-cricket.php:57
filtersportspress_event_performance_show_footersportspress-for-cricket.php:58
filtersportspress_event_performance_table_total_valuesportspress-for-cricket.php:59
actionsportspress_after_event_performance_tablesportspress-for-cricket.php:62
filtersportspress_event_logo_optionssportspress-for-cricket.php:65
filtersportspress_event_logos_team_resultsportspress-for-cricket.php:66
filtersportspress_event_team_result_adminsportspress-for-cricket.php:67
filtersportspress_calendar_team_result_adminsportspress-for-cricket.php:68
filtersportspress_event_list_main_resultssportspress-for-cricket.php:69
filtersportspress_event_blocks_team_result_or_timesportspress-for-cricket.php:70
filtersportspress_main_results_or_timesportspress-for-cricket.php:71
filtersportspress_main_resultssportspress-for-cricket.php:72
actionsportspress_after_event_logossportspress-for-cricket.php:75
filtersportspress_default_sportsportspress-for-cricket.php:78
Maintenance & Trust

SportsPress for Cricket Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 27, 2020
PHP min version
Downloads19K

Community Trust

Rating90/100
Number of ratings2
Active installs600
Developer Profile

SportsPress for Cricket Developer Profile

ThemeBoy

12 plugins · 21K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
360 days
View full developer profile
Detection Fingerprints

How We Detect SportsPress for Cricket

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sportspress-for-cricket/js/sportspress-cricket.js/wp-content/plugins/sportspress-for-cricket/js/admin.js/wp-content/plugins/sportspress-for-cricket/css/admin.css/wp-content/plugins/sportspress-for-cricket/css/sportspress-for-cricket.css
Generator Patterns
SportsPress for Cricket
Version Parameters
sportspress-cricket.js?ver=1.1.4sportspress-cricket-admin.js?ver=1.1.4sportspress-cricket-admin.css?ver=0.9sportspress-for-cricket.css?ver=1.1.4

HTML / DOM Fingerprints

CSS Classes
sp-cricket-resultssp-cricket-event-score-statussp-cricket-event-outcome
JS Globals
sp_cricket_settings
Shortcode Output
<!-- BEGIN SP CRICKET RESULTS --><!-- END SP CRICKET RESULTS --><!-- BEGIN SP CRICKET EVENT SCORE STATUS --><!-- END SP CRICKET EVENT SCORE STATUS -->
FAQ

Frequently Asked Questions about SportsPress for Cricket